Rebecca Byrnes — Cybersecurity & Compliance

Cybersecurity, Information Security Compliance (ISO 27001, SOC 2), based in Portugal


Projects

ISO 27001 Program Build-out

End‑to‑end ISO 27001 implementation, from gap analysis and risk assessment to ISMS documentation and successful certification.

iso27001 risk isms

SOC 2 Readiness and Evidence Automation

Designed SOC 2 controls and automated evidence collection across CI/CD, cloud, and HR systems to reduce audit prep time.

soc2 automation audit

Vendor Risk Management (TPRM)

Built a third‑party risk process with intake forms, risk tiers, and continuous monitoring for critical vendors.

tprm governance risk

Secure SDLC Enablement

Introduced threat modeling, SAST/DAST, and security gates in pipelines; shipped developer playbooks and training.

ssdcl devsecops appsec

Policies and Awareness Program

Authored policy suite (AUP, Access Control, Cryptography, BYOD, Incident Response) and delivered engaging awareness campaigns.

policies awareness training